Cloudpense works with AWS under a shared, layered security model designed to provide robust protection.
·Cloudpense Protection: network access controls, login audits, asset management, customer operating system updates, anti-malware protection and IDS/IPS backup settings.
·AWS Protection: 24/7 security, restricted access, two-factor authentication, secure disk destruction, intrusion detection, security inspections, network monitoring and secure API endpoints.


·Physical Servers: SSH access; all operations are logged and auditable; hardened operating systems with unnecessary ports closed.
·EC2: security groups, network isolation, key protection and Hillstone attack protection.
·VPC: custom networking, ACL access controls and VPN-encrypted access.
·Storage encryption.
·Multi-region deployment.
·Authorization: IAM users, roles and groups control access to resources.
·Auditing: API and manual operations are audited, along with resource changes.
·Physical Servers: SSH access; all operations are logged and auditable; hardened operating systems with unnecessary ports closed.
·EC2: security groups, network isolation, key protection and Hillstone attack protection.
·VPC: custom networking, ACL access controls and VPN-encrypted access.
·Storage encryption.
·Multi-region deployment.
·Authorization: IAM users, roles and groups control access to resources.
·Auditing: API and manual operations are audited, along with resource changes.

To meet enterprise requirements for data isolation and independent management, Cloudpense offers a hybrid cloud architecture that keeps data fully independent while sharing the SaaS application layer. Customers retain 100% data ownership, management capabilities and monitoring rights, helping prevent unauthorized access, data loss and tampering. This approach combines the benefits of SaaS with stronger control over data security.


Cloud services and internal systems use a three-layer security architecture to protect data exchanged through interfaces:
·Infrastructure Security: 1. Physical firewalls restrict communication by IP address; 2. Bastion hosts isolate internal and external network communications.
·Transport Security: all communications use the HTTPS encryption protocol to protect data against interception and tampering. Additional controls include lockouts after failed login attempts, Touch ID, Face ID and third-party authentication.
·Application Layer Security: identity token and business logic validation help ensure the integrity and validity of interface requests.
Cloud services and internal systems use a three-layer security architecture to protect data exchanged through interfaces:
·Infrastructure Security: 1. Physical firewalls restrict communication by IP address; 2. Bastion hosts isolate internal and external network communications.
·Transport Security: all communications use the HTTPS encryption protocol to protect data against interception and tampering. Additional controls include lockouts after failed login attempts, Touch ID, Face ID and third-party authentication.
·Application Layer Security: identity token and business logic validation help ensure the integrity and validity of interface requests.

·Each node uses dual-system hot standby. Disaster recovery across two separate AWS Availability Zones helps deliver up to 99.5% system availability.
·Amazon S3 storage provides up to 11 nines of data durability. Regular disk snapshots and data backups further protect business data.


The platform architecture supports high concurrency and scales efficiently. Replicating application nodes quickly expands computing and service capacity while maintaining a responsive user experience.
In stress tests with 5,000 concurrent users, the system maintained an average response time of about 2 seconds.
The platform architecture supports high concurrency and scales efficiently. Replicating application nodes quickly expands computing and service capacity while maintaining a responsive user experience.
In stress tests with 5,000 concurrent users, the system maintained an average response time of about 2 seconds.




